We're delighted to announce that Single Sign-On (SSO) beta is now live đ
Summarising the initial SSO beta requirements:
To ensure a smooth beta experience, please take a look at the following initial requirements to make sure it's a good fit:
Manual user provisioning is required. SSO covers authentication only â account admins still need to create and remove users in RotaCloud.
SSO applies to all users on your account â mixed login methods aren't currently supported. Email addresses must match those held in your SSO provider, though multiple email domains are supported provided all users are within the same identity provider.
We're using OpenID Connect for user authentication.
All users must be on the latest mobile app versions, otherwise they won't be able to log in to RotaCloud.
Accounts using the Terminal app must be on the latest Terminal app version.
2FA (Two-factor authentication) within RotaCloud will be disabled because this would be part of the SSO provider flow.
Session expiry â there are no changes to this; existing policies still apply.
How do I setup and enable SSO?
To setup SSO within RotaCloud, you'll need to follow these steps:
Create a new application in your identity provider using OpenID Connect (OIDC). If prompted, select the Authorisation Code flow and enable PKCE.
Add the following redirect or callback URL exactly as shown: https://api.rotacloud.com/v2/auth/sso/callback
Allow the application to use the following scopes:
openid,profile, andemailMake sure your providerâs user information includes:
sub: a unique, permanent identifier for the user
email: the userâs email address in RotaCloud
Within the RotaCloud settings page, select 'Enable SSO on your account' (below the 2FA section), then enter the Issuer URL, Client ID and Client Secret from your SSO provider.
Do not include /.well-known/openid-configuration because RotaCloud adds this automatically.
Users must already have a RotaCloud account with an email address that matches the one returned by your identity provider. SSO does not create new RotaCloud users automatically.
How do existing employees login once SSO is enabled?
As soon as SSO is enabled, all users will be logged out and required to log in via their SSO credentials instead.
How do I add new employees?
Adding someone to your SSO provider doesn't add them to RotaCloud, so you'll need to add them in RotaCloud too. You can choose whether or not to send an invite, though the 'Onboarding' invite option isn't available with SSO enabled. Once invited, they'll receive a welcome email with a 'Sign-in' link. They then enter their email on the login page, and your SSO provider completes the login to RotaCloud.
What if employees belong to multiple accounts?
Anyone linked to multiple RotaCloud accounts can still switch between them as normal, whether or not each one has SSO enabled. If they've been inactive for a while, they'll be asked to log in again.
How do I delete an employee from RotaCloud?
During the beta, removing someone from your SSO provider doesn't remove them from RotaCloud, so you'll need to delete them here too otherwise they can still log in until their login authentication expires. We're working on this during the beta.
How do I disable SSO on my account?
You can turn SSO off at any time by unselecting 'Enable SSO on your account'. When you do:
We'll delete your SSO provider details, so you'll need to re-enter them if you enable SSO
Everyone on your account will need to log back in with their RotaCloud email and password they used before SSO was enabled
Anyone added while SSO was enabled won't have a password yet. They should use the âForgot passwordâ flow on the login page (once theyâve entered their email) to create one.
Should you need to disable SSO on your account, it would be great to hear from you to understand why.
How do I provide feedback during the beta?
During this time, we'll be hugely grateful if you could share feedback, progress and raise any issues should they arise.
When sharing feedback or reporting any issues, this should be done via the 'Live Chat' messenger within RotaCloud.
We'll also check-in during the beta to understand the impact of SSO, and keep you updated on improvements as they're released.
How does the pricing work?
Beta participants will have SSO free for 12 months. After that, pricing will be introduced in line with our existing add-ons â the exact structure is still being finalised.
Thank you so much for indicating your interest in SSO, where we look forward to speaking with you during the beta.
Many thanks
RotaCloud Product Team
